Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A managed security service provider (MSSP) is advising a client on improving endpoint security for their distributed workforce. The client uses various operating systems (Windows, macOS, Linux) and needs a solution that provides advanced threat detection, real-time visibility into endpoint activities, and automated response capabilities across all these platforms. Which technology best meets these requirements for comprehensive endpoint protection and response?

  1. ATraditional Antivirus
  2. BEndpoint Detection and Response (EDR)
  3. CSystem Information and Event Management (SIEM)
  4. DVulnerability Scanner
Show answer & explanation

Correct answer: B. Endpoint Detection and Response (EDR)

Endpoint Detection and Response (EDR) solutions are designed to provide advanced threat detection, real-time visibility into endpoint activities (process execution, network connections, file changes), and automated response capabilities across diverse operating systems. This goes beyond traditional antivirus by focusing on active threats and providing forensic data.

Why the other options are wrong

  • A. Traditional Antivirus primarily relies on signatures and lacks real-time visibility and advanced response capabilities across OS types.
  • C. SIEM aggregates logs from various sources but doesn't provide direct endpoint visibility and response capabilities in the same way EDR does.
  • D. A Vulnerability Scanner identifies weaknesses but does not provide real-time threat detection or response capabilities.

Endpoint Detection and Response (EDR)

An integrated endpoint security solution that continuously monitors and collects data from endpoint devices, providing advanced threat detection, investigation, and automated response capabilities to security incidents.

  • Offers real-time visibility into endpoint activities (processes, network, files).
  • Detects advanced threats like fileless malware and APTs.
  • Provides automated and manual response actions (e.g., isolate, kill process, remediate).

Memory trick: EDR is like a smart security camera with a built-in alarm and a responding officer for every endpoint.

More Endpoint Security questions